CISO
Chief Information Security Officer (CISO)
About Keka
Keka is a SaaS HRMS platform, helping companies manage the entire employee lifecycle efficiently – hiring, onboarding, time & attendance, payroll, performance, and learning in one integrated system.
We have been in the market for 10+ years and serve customers across India, the GCC, and the US. As we continue to move upmarket into regulated enterprise segments, security is becoming a critical part of how we build trust and win enterprise customers.
Role Summary
We are looking for a Chief Information Security Officer (CISO) to lead Keka's security strategy and help us scale securely into regulated enterprise markets.
This is a senior leadership role responsible for building and maturing Keka's security function across governance, product and platform security, security operations, compliance, privacy, and AI security.
You will work closely with the CEO, CTO, CRO, Product, Engineering, Legal, and Customer teams, while representing Keka with enterprise customers, auditors, regulators, and security leadership teams.
The CISO will own the security posture of Keka, drive enterprise readiness, strengthen our security architecture and engineering practices, and make security a business enabler rather than a blocker.
What You'll Do
- Define and execute Keka's overall security strategy aligned with business and enterprise growth.
- Build enterprise trust and enable revenue by establishing security deal-desk processes, evidence libraries, and a Trust Centre.
- Own security and compliance requirements for regulated customers, including SOC 2 Type II, ISO 27001, RBI requirements, CERT-In directions, and DPDP Act/Rules.
- Partner with enterprise customers, their CISOs, risk teams, auditors, and legal teams on security assessments and contractual security requirements.
- Drive product and platform security across identity and access management, tenant isolation, key management, SSO/SAML, SCIM, MFA, privileged access, and segregation of duties.
- Raise application and SDLC security maturity through threat modelling, SAST/DAST/SCA, vulnerability management, secrets management, release gates, SBOM, and software supply-chain security.
- Build and mature security operations, including 24×7 monitoring, detection engineering, incident response, and insider/privileged-access risk management.
- Own security incident command and ensure incident response processes meet regulatory and contractual notification requirements.
- Drive disaster recovery, ransomware readiness, backup resilience, and CXO-level security tabletop exercises.
- Establish security and privacy governance for Keka's AI initiatives, including model providers, data usage, retention, residency, sub-processors, prompt injection, tool access, tenant isolation, and auditability.
- Build and scale the security organization through a clear govern, build, and run operating model and a Security Champions network across engineering.
- Own the security budget and communicate security risks, investments, and priorities to the executive leadership and Board/Audit Committee.
What You Bring
- 14–20 years of experience in security and compliance, with 5+ years of owning a security function at a CXO/Board level.
- Strong hands-on experience leading SOC 2 Type II and ISO 27001 audits end-to-end, including scoping, evidence, exceptions, and auditor negotiations.
- Experience being the accountable security leader for enterprise or BFSI customer audits, including on-site or right-to-audit exercises.
- Strong understanding of multi-tenant SaaS security, tenant isolation, identity, access management, and key-management architecture.
- Strong cloud security experience at scale, preferably on Azure, covering identity, network isolation, secrets, key management, policy-as-code, and security posture management.
- Strong working knowledge of RBI IT governance/outsourcing requirements, CERT-In directions, and DPDP Act & Rules.
- Experience building or significantly maturing 24×7 security monitoring and incident response, including handling incidents requiring external notification.
- Proven ability to improve application and SDLC security across a large engineering organization.
- Experience building, structuring, and scaling a security organization.
- Strong executive communication skills, with the ability to communicate security risks and trade-offs to the Board and business leadership.
Good to Have
- Experience with multi-tenant B2B SaaS at production scale.
- Experience taking a SaaS platform from mid-market into regulated enterprise segments.
- Experience in HR, payroll, fintech, insurance, healthcare, or other highly regulated data environments.
- Exposure to Saudi PDPL/SDAIA/NCA, SAMA, UAE PDPL, DIFC/ADGM requirements.
- Experience with HIPAA/BAA, GDPR, and EU AI Act.
- Exposure to ISO 27701, ISO 22301, ISO 42001, NIST AI RMF, SOC 1/ISAE 3402.
- Experience with security of AI-assisted development and agentic/AI pipelines.
- Experience with cyber insurance placement and claims.
- CISSP, CISM, CISA or equivalent certifications are useful but not mandatory.
- A prior CISO title is not mandatory; strong Head of Security or Deputy CISO experience can also be relevant.
What Will Help You Succeed in This Role
- Keka is moving into larger and more regulated enterprise segments, so you should be comfortable operating where security directly impacts revenue, customer trust, and deal velocity.
- You should be equally comfortable discussing security strategy with the Board and CEO and going deep into architecture with engineering teams.
- The role requires someone who can identify gaps honestly, prioritize them based on business risk, and drive execution rather than simply create compliance plans.
- Strong customer orientation is critical — you will regularly engage with customer CISOs, risk committees, auditors, and enterprise security teams.
- Keka is growing rapidly, and several security capabilities are being matured. You should be comfortable building from a baseline, operating in ambiguity, and creating scalable processes and teams.
- You should be able to balance security rigor with business velocity and know when to hold the line versus accept a risk with a clear mitigation plan.
Who You'll Work With
- Reports to: CTO
- Executive stakeholders: CEO, CTO, CRO, CFO
- Works closely with: Engineering, Product, Legal, Sales, Customer Experience, Compliance, and the Principal Architect
- External stakeholders: Enterprise customer CISOs, auditors, regulators, and security/risk teams.